JWT Decoder
Decode a JSON Web Token to read its header and payload, see when it expires, and verify HS256/384/512 signatures. Runs entirely in your browser.
eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFzaGEgUGF0ZWwiLCJlbWFpbCI6ImFzaGFAZXhhbXBsZS5jb20iLCJyb2xlcyI6WyJlZGl0b3IiXSwiaWF0IjoxNzYwMDAwMDAwLCJleHAiOjQxMDI0NDQ4MDB9.Ffhu5dYsDXsjDSFpu8wvKm_m_32PoVfRRyVhtwRuwKE
Header
| Claim | Value |
|---|---|
| algSigning algorithm | HS256 |
| typToken type | JWT |
Payload
| Claim | Value |
|---|---|
| subSubject: the user or entity the token is about | 1234567890 |
| nameFull name | Asha Patel |
| emailEmail address | asha@example.com |
| rolesRoles assigned to the subject | ["editor"] |
| iatIssued at | 1760000000Oct 9, 2025, 8:53:20 AM UTC |
| expExpiration time | 4102444800Jan 1, 2100, 12:00:00 AM UTC |
Signature
Enter the shared secret to check the HS256 signature. The check runs in your browser with the Web Crypto API. The demo tokens use .
Ffhu5dYsDXsjDSFpu8wvKm_m_32PoVfRRyVhtwRuwKE
What Is a JWT?
A JSON Web Token (JWT, defined in RFC 7519) is a compact, URL-safe string used to pass identity and permissions between systems, most often as an OAuth 2.0 access token or an OpenID Connect ID token. It has three parts separated by dots, each base64url encoded:
- Header: JSON describing the token: the signing algorithm (alg), the type (typ) and often the key ID (kid).
- Payload: JSON "claims" about the user and the token, such as sub, iss, aud and the exp expiry time.
- Signature: Proves the header and payload were not changed. It is created with a secret (HS256) or a private key (RS256, ES256).
Registered Claims
| Claim | Name | Meaning |
|---|---|---|
| iss | Issuer | Who created the token, usually your identity provider’s URL |
| sub | Subject | The user or service the token is about |
| aud | Audience | Which API or app should accept the token |
| exp | Expiration | After this time the token must be rejected |
| nbf | Not before | Before this time the token must be rejected |
| iat | Issued at | When the token was created |
| jti | JWT ID | A unique ID, used to stop the same token being replayed |
How to Decode a JWT
- Paste the token, or a whole
Authorization: Bearer …header. - Read the header and payload as a claims table or as formatted JSON, and copy either one.
- Check the status: whether the token has expired or is not valid yet, with dates in your local time.
- Verify the signature of an HS256, HS384 or HS512 token by entering its secret.
Frequently Asked Questions
- Is it safe to paste my JWT here?
- The decoder runs entirely in your browser and the token is never sent to a server. Even so, a live access token works like a password until it expires, so prefer test tokens and never share production tokens in screenshots or tickets.
- Does decoding a JWT verify it?
- No. The header and payload are only base64url encoded, so anyone can read them. A token is trustworthy only after your server checks the signature, the expiry (exp and nbf), the issuer (iss) and the audience (aud). This tool can check HS256, HS384 and HS512 signatures if you enter the shared secret.
- Are JWTs encrypted?
- Normal signed tokens (JWS, three parts) are not encrypted, so never put passwords or other secrets in the payload. Encrypted tokens (JWE) have five parts; this tool shows their header but cannot read the payload without the key.
- What format are exp, iat and nbf in?
- They are "NumericDate" values: the number of seconds since 1 January 1970 UTC. The decoder converts them to your local time and shows how long ago or how soon they are. A value in milliseconds is a common bug, and the tool warns about it.
- Why can’t I verify an RS256 or ES256 token here?
- Those tokens are signed with a private key and checked with the issuer’s public key, usually published at a JWKS URL. Use your JWT library on the server for that check; this page decodes them and shows the signature.
- What does "alg": "none" mean?
- The token has no signature at all. Servers must never accept unsigned tokens, and RFC 8725 recommends that libraries only allow the algorithms you expect. The decoder flags these tokens with a warning.
- Can I paste a whole Authorization header?
- Yes. A leading "Authorization:" or "Bearer " and any surrounding quotes or spaces are removed before decoding.
Sources & Standards
Claim names and validation advice follow the IETF and OpenID specifications below. Last reviewed .
- RFC 7519: JSON Web Token (JWT)
- RFC 7515: JSON Web Signature (JWS)
- RFC 8725: JWT Best Current Practices
- OpenID Connect Core 1.0: standard claims
Decoding other encodings? Try the Base64 Decoder or the URL Decoder.